Vulnerabilities > CVE-2016-2515 - Resource Management Errors vulnerability in Hawk Project Hawk 3.1.2/4.1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
Hawk before 3.1.3 and 4.x before 4.1.1 allow remote attackers to cause a denial of service (CPU consumption or partial outage) via a long (1) header or (2) URI that is matched against an improper regular expression.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Common Weakness Enumeration (CWE)
References
- http://www.openwall.com/lists/oss-security/2016/02/20/1
- http://www.openwall.com/lists/oss-security/2016/02/20/1
- http://www.openwall.com/lists/oss-security/2016/02/20/2
- http://www.openwall.com/lists/oss-security/2016/02/20/2
- https://bugzilla.redhat.com/show_bug.cgi?id=1309721
- https://bugzilla.redhat.com/show_bug.cgi?id=1309721
- https://github.com/hueniverse/hawk/commit/0833f99ba64558525995a7e21d4093da1f3e15fa
- https://github.com/hueniverse/hawk/commit/0833f99ba64558525995a7e21d4093da1f3e15fa
- https://github.com/hueniverse/hawk/issues/168
- https://github.com/hueniverse/hawk/issues/168
- https://nodesecurity.io/advisories/77
- https://nodesecurity.io/advisories/77